CKS Supply Chain Security Practice Question
A cluster administrator wants to allow only images from a specific registry (e.g., 'myregistry.io') to be deployed in the cluster. Which tool can be used to enforce this via admission control?
⚠ Common exam trap
Many exam-takers confuse Helm (a deployment tool) with an admission controller, or assume Calico (a network policy tool) can enforce image registry restrictions, when only OPA/Gatekeeper or similar admission webhooks can perform this validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OPA/Gatekeeper
OPA/Gatekeeper is a Kubernetes admission controller that allows you to enforce custom policies, such as restricting container images to a specific registry. By defining a ConstraintTemplate and a Constraint that checks the image prefix (e.g., 'myregistry.io/'), Gatekeeper can reject any Pod creation that uses images from unauthorized registries. This directly addresses the requirement for registry-based admission control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
OPA/Gatekeeper
Why this is correct
OPA/Gatekeeper is a validating admission webhook that intercepts API requests before they are persisted. It uses ConstraintTemplates written in Rego to define policies, such as restricting container images to a trusted registry, and Constraints to enforce them across namespaces. Because it integrates directly with the API server's admission phase, it can block any Pod that references an image outside the approved allowlist.
- ✗
Helm
Why it's wrong here
Helm is a Kubernetes package manager that installs and upgrades applications as charts, but it does not sit in the API request path. Helm is not an admission controller and cannot evaluate or reject resource definitions based on policy. Its templating and rendering features influence what gets deployed, but once a manifest is submitted, Helm has no authority to validate image provenance or registry membership.
- ✗
Calico
Why it's wrong here
Calico is a container networking and network policy solution that enforces rules at Layers 3/4, typically using eBPF or iptables, to control traffic between workloads. It does not act as an admission controller and cannot inspect or modify Pod creation requests. Restricting image registries is a workload-level admission decision, not a network dataplane function, so Calico cannot perform this requirement.
- ✗
Prometheus
Why it's wrong here
Prometheus is a monitoring and alerting system that scrapes time-series metrics from endpoints and stores them for queries and visualization. It lacks any mechanism to intercept Kubernetes API requests or run admission control policies. While Prometheus can alert on events like workloads running unapproved images, it observes retrospectively rather than preventing admission, so it cannot enforce an image registry allowlist.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An admin runs 'kubectl run nginx --image=nginx' and the pod fails with 'ImagePullBackOff'. The cluster has an OPA/Gatekeeper constraint that only allows images from 'myregistry.io'. How can the admin quickly test the restriction?
medium- A.Delete the OPA constraint
- B.Add a label 'allowlist=true' to the pod
- ✓ C.Use an image from 'myregistry.io/nginx:latest'
- D.Use 'kubectl run nginx --image=nginx --validate=false'
Why C: The OPA/Gatekeeper constraint explicitly restricts allowed images to those from 'myregistry.io'. By specifying an image from that registry (e.g., 'myregistry.io/nginx:latest'), the admin can quickly verify that the constraint permits compliant images. This tests the policy's intended behavior without altering or bypassing the constraint.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.